595 Episoden
- Today we are talking about GovHub, Drupal in Government, and Why Governments Love Drupal with guest Jasmyne Epps. We'll also cover Convivial Gov Site Template as our module of the week.
For show notes visit:
https://www.talkingDrupal.com/571
Topics
GovHub Origins and Goals
Feature Requests and Governance
Why Government Chooses Drupal
Team Structure and Release Cadence
Accessibility and Compliance Strategy
Hosting Model and Multisite
Structured Content and Microcontent
Syndication and Emergency Alerts
Orchard Design System Explained
Training and Onboarding Editors
Gov Talks Conference
Logo Specs and Releases
Ticket Prioritization PRICE
QA Workflow with Tugboat
Handling Traffic Spikes
Drupal 11 Performance Talk
Drupal 11 Upgrade Gotchas
Getting Users Excited
Translation Strategy Limits
Why Government Loves Drupal
Resources
GovHub
The Bug Stops Here — The State of Georgia Shifts Left (GovCon 2025 presentation with Jasmyne Epps and James Sansbury)
Accelerating an ambitious migration and development project (GovHub + Tugboat migration story)
Logo page
Public facing knowledge base
Orchard design system
(P)Rice (P)olitics - (R)each - (I)mpact - (C)onfidence - (E)ffort
Luma
Guests
Jasmyne Epps - jasmyneepps.com jasmyneepps
Hosts
Nic Laflin - nLighteneddevelopment.com nicxvan
John Picozzi - epam.com johnpicozzi
Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
MOTW
Correspondent
Martin Anderson-Clutz - mandclu.com mandclu
Brief description: Have you ever wanted to stand up a polished, accessible government website in Drupal (with components, content types, SEO, and cookie consent all wired up) without writing any code? There's a site template for that.
Module name/project name: Convivial Gov
Brief history Created in March 2026 by Morpht, the shop behind the Convivial family — with Ivan Zugec leading the maintainer team.
Versions available: 1.3.3, which works with Drupal 11
Maintainership Actively maintained: release just last week, on September 16th
Security coverage
Test coverage: functional tests for install and validation, plus a kernel requirements test.
Documentation there's a full handbook over at docs.morpht.com, and a live demo at gov.convivial.io
Open issues: none?
Site template features and usage Like the Haven site template we talked about a couple of weeks ago, Convivial Gov gives you a curated stack plus demo content, and in this case hands you a robust, ready-to-customize government site.
Because it's built on Drupal CMS, you get all the latest Drupal tooling: Canvas for visual page building, Single Directory Components, and Recipes.
The front end is Morpht's Morphos theme, built on Tailwind and DaisyUI, so you get dark mode, multiple colour palettes, and a big library of editor-friendly components out of the box. It's worth mentioning that using the Morphos theme on a production site requires a paid license
The provided components are sorted into six buckets: container, content, child, element, background, and behavior. They include fun ones like scroll reveal and a colour palette switching behavior
The content model is broad. You get seven content types: Page, Section, Article, Publication, Resource, Topic, and Audience. And, they come with a stack of teaser and card view modes to display them.
The whole point is no-code: a site builder can compose sophisticated pages in Canvas without ever touching a template.
One thing to watch: the default timezone is Australia/Sydney out of the box
It's also worth comparing Convivial Gov to another site template called Local. Both dropped in March 2026, both are Canvas-based Drupal CMS site templates for the public sector, and both lean on ECA for automation — so there's real common ground. The difference is scope and mechanism. Local, from Annertech, is narrowly purpose-built for local councils and community-service directories: it ships a specific service information architecture — Service and Service Landing content types — with ECA wired so section pages stay in sync when service pages get published or updated, taking its cues from the gov.uk design system. Convivial Gov goes the other way — it's design-system-led and general-purpose, a broad component library and content model meant for any government, agency, or marketing site rather than one particular workflow. - Today we are talking about Laravel, Marketing, and The PHP Foundation with guest Matt Stauffer. We'll also cover Formdazzle as our module of the week.
For show notes visit:
https://www.talkingDrupal.com/570
Topics
What Is Laravel
Writing Laravel Books
AI and Technical Writing
Laravel Versus CMS
Drupal as Framework
Integrating Laravel and CMS
Laravel and Symfony
Marketing Modern PHP
Laravel Community Marketing
Jigsaw and Onramp
Drupal Marketing Lessons
Onboarding Focus in Laravel
Laravel BDFL Changes
Onboarding And Docs
Drupal Framework Perception
What PHP Foundation Does
Marketing PHP Vs Laravel
AI Answers And Positioning
Cross Ecosystem Collaboration
Resources
Jigsaw
Onramp
Native php
Alpine
Tailwind
Vue
Laravel herd
php.new
Blog post on how to contribute to php
Laracon talk
Kent C. Dodds The Last Software Engineer (how in the AI era, we need to all become Product Engineers)
Guests
Matt Stauffer - mattstauffer.com
Hosts
Nic Laflin - nLighteneddevelopment.com nicxvan
John Picozzi - epam.com johnpicozzi
Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
MOTW
Correspondent
Bernardo Martinez - bernardm28
Brief description: This week's module is Formdazzle, a developer tool that makes theming Drupal forms easier.
Drupal's Form API is a powerful abstraction, but when you want to target one specific field, label, button, or form wrapper, the default Twig template suggestions can be limited.
The module works by taking information Drupal already knows about the form, like the form ID, element type, and element name, and using that to generate more targeted Twig template suggestions.
For example, in a Drupal View with exposed filters, you may want to style the Reset button differently from the Submit button. By default, Drupal renders both buttons through the same input–submit.html.twig template, which makes it difficult to customize them independently. This module lets you assign different templates to individual form buttons—such as Submit, Reset, or Filter—based on their action, type, and other properties.
This module has no configuration. Just enable the module and it starts working and look at the twig debug comments including extra template suggestions.
Module name/project name: formdazzle
Brief history How old: created in 13 September 2019 by johnalbin
Versions available: ^10.1 ^11 ^12
Maintainership Actively maintained
Last release was 1 September 2026, currently the module has two maintainers Stephen Mustgrave and John Albin.
The module includes both test and security coverage.
Usage stats: 3,956 according to drupal.org
Module features and usage There's no configuration. Just enable the module and it starts working, including with Views exposed forms and Webform.
Formdazzle automatically adds more specific theme suggestions based on the form ID, element type, and element name. - On today's show we are talking about Site Templates, What they do, and How you can use them with guests Tim Lehnen & Adam Globus-Hoenich. We'll also cover Haven as our module of the week.
For show notes visit:
https://www.talkingDrupal.com/569
Topics
MOTW: Haven
What Site Templates Are
Canvas Components Included
Promoting Templates Beyond Drupal
Templates vs Distributions
Who Benefits from Templates
Template Types and Adoption
Where to Find Templates
Featured vs Installer List
Free vs Paid Templates
Recipes vs Templates
Distributions and Themes
Empowering Site Builders
Exporting a Template
Designing for Users
Releases Without Upgrades
Best Practices and AI
How to Contribute
Resources
Webinar: Drupal Canvas and Agentic Content Management: What Enterprise Teams Need to Know
Drupal Site Templates
Tim's book - Fog & Fireflies
Guests
Tim Lehnen - @TimLehnen hestenet
Adam Globus-Hoenich - @PhenaProxima phenaproxima
Hosts
Nic Laflin - nLighteneddevelopment.com nicxvan
Stephen Cross - SecondSginalMedia.com [stephencross]](https://www.drupal.org/u/stephencross)
Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
Module of the Week
Correspondent
Martin Anderson-Clutz - mandclu.com mandclu
Haven - Site Template - Designed for non-profit sites, this template features a bright, warm design that can be adapted for many use cases. It comes pre-confifgured with blog, projects and people profiles, as well as newsletter signup, donation add-ons and more. - Today we are talking about Drupal Performance, Rapid Development, and Drupal Canvas Maturity with our hosts. We'll also cover Microsoft 365 FullCalendar as our module of the week.
For show notes visit:
https://www.talkingDrupal.com/568
Topics
Deprecating Module Theme Files
Migrating Hooks to Classes
Why This Change Matters
Drupal Performance Gains
Performance Audits and Lighthouse
Automating Checks and Spreadsheet Rant
AI Spreadsheet Cautionary Tale
Privacy Concerns with AI
Freelancer Pressure
Rapid Change Reality
Canvas Release Risks
Community Support Needed
AI For Documentation
Canvas Production Readiness
Canvas Architecture Debate
AI For Voting Research
LLM Bias And Sources
Resources
Rebrickable
Webpagetest
Lighthouse
Tugboat
Drupal canvas
Guests
Martin Anderson-Clutz - mandclu.com mandclu
Hosts
Nic Laflin - nLighteneddevelopment.com nicxvan
John Picozzi - epam.com johnpicozzi
Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
MOTW
Correspondent
Martin Anderson-Clutz - mandclu.com mandclu
Brief description: Have you ever wanted your users' own Outlook calendars to show up right alongside your Drupal content in a calendar view? There's a module for that.
Module name/project name: Microsoft 365 FullCalendar
Brief history How old: created just last month, August 19 2026, by fabianderijk of Finalist
Versions available: 1.0.0, which works with Drupal 11
Maintainership Brand new — the first and only release is from last month, and the whole commit history is basically launch day
Security coverage: brand new, so not yet
Test coverage: yes, both unit tests and kernel tests
Documentation: a genuinely thorough README — it walks through privacy, the config guard rails, and three different ways to customize event output
Open issues: none yet, it's less than two weeks old
Usage stats: Too new for a site count
Module features and usage With this installed, it adds the signed-in user's Microsoft 365, or Outlook, calendar as an extra event source on a FullCalendar view — so their personal appointments sit right next to the Drupal content the view already renders
It leans on the Microsoft 365 Connector module and its SSO submodule, plus the FullCalendar module. Each user must have signed in through Microsoft 365 SSO: anyone who hasn't just sees no events, which is a clean fallback
It uses lazy loading, so it only fetches events in the date range the calendar is currently showing, not your whole calendar
Privacy is baked in: anything marked private or confidential in Outlook is masked, so it shows up as just "Busy", with no title, location, or meeting link, unless the site builder deliberately turns masking off
The response itself is per-user and marked private, no-store, so it never lands in a shared or CDN cache
There's a clever server-side cache too: it stores the raw Graph response before masking, so a single fetch can serve several displays that each have different masking settings
You get guard rails you can tune with Drush or an admin form: max events, max date range, cache lifetime, and a separate, shorter failure cache
That failure cache is a nice touch — if there's no active Microsoft session, or Graph errors out, it caches the empty result briefly so a broken connection doesn't get re-polled on every single calendar click
Under the hood it calls Graph's calendarView endpoint rather than /me/events, which means recurring meetings get expanded into their individual occurrences — exactly what a calendar grid needs
Every event carries CSS classes for its status — busy, free, tentative, out-of-office, working elsewhere, cancelled — so you can style them however you want
And if CSS isn't enough, there's a server-side alter hook and a JavaScript pre-build event for fully custom rendering. Nice detail: the hook is explicitly guarded so you can't use it to put back a title or location that masking just stripped out
Clearly this will be more useful for edge cases, for example an intranet, but I think this is a really interesting example of the power of Drupal as an integration layer, or as some like to put it, the "glass" through which a user can interact with multiple systems - Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week.
For show notes visit:
https://www.talkingDrupal.com/567
Topics
What Are CVEs
CVE Lifecycle and Disclosure
AI Era Security Challenges
What CVE Program Excludes
Patch Fast Reality
Global Security Signals
CVE Timing Judgment
KEV Flags Explained
CVE Updates Link Rot
Who Decides CVE
Sneaky Patch Dangers
ADP Program Fixes
Small Team Triage
Vulnerability Tsunami AI
Autonomous Security Future
Legal Pressure Budgets
Resources
Psalm PHP Static Analysis Tool
SARIF format
PHP ecosystem
Council of roots
How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed
CVE podcast
Vulncon
PSIRT
Guests
David Welch - github: dwelch2344 dwelch2344
Hosts
Nic Laflin - nLighteneddevelopment.com nicxvan
John Picozzi - epam.com johnpicozzi
JD Flynn - dorficus
MOTW
Correspondent
Martin Anderson-Clutz - mandclu.com mandclu
Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that.
Module name/project name: Security Scanner
Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia
Versions available: 1.0.0, which works with Drupal 10.3 and 11
Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July
Security coverage
Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories
Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG
Number of open issues: 1 issue, not a bug
Usage stats: 2 sites (it's brand new)
Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review
It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets
Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan
One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives
The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code
Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log
For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them
It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook
And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship
Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review
I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more
Weitere Technologie Podcasts
Trending Technologie Podcasts
Über Talking Drupal
Talking Drupal is a weekly chat about web design and development by a group of people with one thing in common: We Love Drupal. With hosts John Picozzi, Nic Laflin, and Martin Anderson-Clutz
Podcast-WebsiteHöre Talking Drupal, Search Engine und viele andere Podcasts aus aller Welt mit der radio.at-App

Hol dir die kostenlose radio.at App
- Sender und Podcasts favorisieren
- Streamen via Wifi oder Bluetooth
- Unterstützt Carplay & Android Auto
- viele weitere App Funktionen
Hol dir die kostenlose radio.at App
- Sender und Podcasts favorisieren
- Streamen via Wifi oder Bluetooth
- Unterstützt Carplay & Android Auto
- viele weitere App Funktionen


Talking Drupal
Code scannen,
App laden,
loshören.
App laden,
loshören.


























